deploy: which host runs the secret store is its own decision
A swarm has one store, so running it is a fact about this machine and belongs beside the other deploy.* toggles rather than in the namespace every host agrees on. Attrset with an enable, not a bare bool, so a second deployment decision has somewhere to go. Asserted from swarm.enableRequiredServices alongside the other once-per-swarm services, and asserted as a mkDefault -- which is what keeps *where* the store runs a separate question from *that* it runs. Set it directly to put the store on a host of its own; a hive that does not run it is a client either way, reaching it by name. Two descriptions in the file still narrated the old swarm.* layout as something that used to be true, and the queue's claimed it belongs on the shared-services host. Both now say what holds.
This commit is contained in:
parent
b103f4c999
commit
a5091c58c0
2 changed files with 39 additions and 5 deletions
|
|
@ -10,9 +10,9 @@
|
||||||
# deploy.* — this machine's deployment decisions. Necessarily different
|
# deploy.* — this machine's deployment decisions. Necessarily different
|
||||||
# on every host, because that is what a deployment is.
|
# on every host, because that is what a deployment is.
|
||||||
#
|
#
|
||||||
# The `enable` toggles used to live under `swarm.*`, which made the
|
# The `enable` toggles live here rather than under `swarm.*` so the
|
||||||
# namespace that is supposed to be identical everywhere carry the one
|
# namespace that is identical everywhere does not carry the one thing
|
||||||
# thing that must differ.
|
# that must differ per host.
|
||||||
#
|
#
|
||||||
# Flat and named for the thing deployed — `deploy.forgejo`, not
|
# Flat and named for the thing deployed — `deploy.forgejo`, not
|
||||||
# `deploy.swarmServices.forgejo`: grouping by "swarm service" re-encodes
|
# `deploy.swarmServices.forgejo`: grouping by "swarm service" re-encodes
|
||||||
|
|
@ -161,6 +161,32 @@ in
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
|
bao.enable = lib.mkOption {
|
||||||
|
type = lib.types.bool;
|
||||||
|
default = false;
|
||||||
|
example = true;
|
||||||
|
description = ''
|
||||||
|
Run the swarm's secret store in a `swarm-bao` container on this
|
||||||
|
host. A swarm has one store and it has to exist somewhere, so
|
||||||
|
this is asserted from
|
||||||
|
{option}`services.hyperhive.swarm.enableRequiredServices`
|
||||||
|
alongside the other once-per-swarm services.
|
||||||
|
|
||||||
|
That assertion is a `mkDefault`, which is what keeps *where* the
|
||||||
|
store runs a separate question from *that* it runs: set this
|
||||||
|
directly to put the store on a host of its own, and clients
|
||||||
|
still reach it by name at
|
||||||
|
{option}`services.hyperhive.swarm.bao.domain` rather than at a
|
||||||
|
local address.
|
||||||
|
|
||||||
|
With it off, this hive is a *client*: it still reads its own
|
||||||
|
secrets from whoever runs the store, authenticating with its own
|
||||||
|
client certificate. Every hive needs the client half; only one
|
||||||
|
runs the server half, which is why the two live in different
|
||||||
|
namespaces.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
authelia.enable = lib.mkOption {
|
authelia.enable = lib.mkOption {
|
||||||
type = lib.types.bool;
|
type = lib.types.bool;
|
||||||
default = false;
|
default = false;
|
||||||
|
|
@ -223,8 +249,9 @@ in
|
||||||
default = false;
|
default = false;
|
||||||
description = ''
|
description = ''
|
||||||
Run the swarm's message queue in a `swarm-nats` container on this
|
Run the swarm's message queue in a `swarm-nats` container on this
|
||||||
host. A swarm has one queue, so this belongs on the same host as
|
host. A swarm has one queue, so at most one host turns this on —
|
||||||
the rest of the shared services.
|
but *which* host is its own decision, not necessarily the one
|
||||||
|
running the swarm's other shared services.
|
||||||
|
|
||||||
Off by default, and off means *absent*: no container is created
|
Off by default, and off means *absent*: no container is created
|
||||||
and nothing else in the evaluated config changes.
|
and nothing else in the evaluated config changes.
|
||||||
|
|
|
||||||
|
|
@ -90,4 +90,11 @@ in
|
||||||
# hive that is not the service host is a *client* of it, not a second one.
|
# hive that is not the service host is a *client* of it, not a second one.
|
||||||
config.services.hyperhive.deploy.victorialogs.enable =
|
config.services.hyperhive.deploy.victorialogs.enable =
|
||||||
lib.mkDefault swarmCfg.enableRequiredServices;
|
lib.mkDefault swarmCfg.enableRequiredServices;
|
||||||
|
|
||||||
|
# The secret store. Once per swarm and optional, so it belongs to the
|
||||||
|
# same switch: a hive that does not run it is a *client*, reading its
|
||||||
|
# own secrets from whoever does. `mkDefault` is what keeps the store
|
||||||
|
# placeable on a host of its own — it can be set directly here and
|
||||||
|
# turned off wherever this switch happens to be on.
|
||||||
|
config.services.hyperhive.deploy.bao.enable = lib.mkDefault swarmCfg.enableRequiredServices;
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue